Description
ReportTemplateService service in Oracle Business Intelligence has an XXE vulnerability. This vulnerability allows an attacker to send crafted requests to a web application for extraction of secrets from the file system, server-side request forgery or denial-of-service attacks.
Remediation
Upgrade to the latest version of Oracle Business Intelligence. This issue was fixed in Oracle Critical Patch Update - April 2019
References
Related Vulnerabilities
Oracle JRE CVE-2018-2795 Vulnerability (CVE-2018-2795)
Mailman Other Vulnerability (CVE-2002-0855)
Mailman Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2016-6893)
Squid Improper Input Validation Vulnerability (CVE-2021-33620)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-9848)